Peter Palfrader [Sun, 15 Jul 2018 08:55:13 +0000 (10:55 +0200)]
fix template
Peter Palfrader [Sun, 15 Jul 2018 08:54:26 +0000 (10:54 +0200)]
Use update-ca-certificates to update ca-global on stretch and later
Peter Palfrader [Sat, 14 Jul 2018 17:54:31 +0000 (19:54 +0200)]
Give us longer to notice degraded boot
Peter Palfrader [Sat, 14 Jul 2018 13:00:33 +0000 (15:00 +0200)]
only run /usr/local/sbin/update-ca-certificates-dsa if it exists
Tollef Fog Heen [Fri, 13 Jul 2018 20:25:50 +0000 (22:25 +0200)]
Allow debadmin to sudo to codesign
Julien Cristau [Mon, 9 Jul 2018 18:06:59 +0000 (20:06 +0200)]
Make salsa.d.o the default ssl vhost on godard so lame clients can get to it
Apparently bzr still doesn't do SNI
(https://salsa.debian.org/salsa/support/issues/90)
Julien Cristau [Sun, 8 Jul 2018 10:39:29 +0000 (12:39 +0200)]
Comment out rate-limiting of https traffic on security-tracker
Julien Cristau [Sat, 7 Jul 2018 12:34:22 +0000 (14:34 +0200)]
Increase https bandwidth for security-tracker
Julien Cristau [Sat, 7 Jul 2018 08:00:59 +0000 (10:00 +0200)]
Keep things cached for at least 10min
Julien Cristau [Sat, 7 Jul 2018 07:47:11 +0000 (09:47 +0200)]
Fix apache module name
Julien Cristau [Sat, 7 Jul 2018 07:10:54 +0000 (09:10 +0200)]
Use mod_cache_disk on security-tracker
Julien Cristau [Fri, 6 Jul 2018 13:10:28 +0000 (15:10 +0200)]
Fix typo in comment
Peter Palfrader [Fri, 6 Jul 2018 09:38:38 +0000 (11:38 +0200)]
drop things from 66.170.99.[12]
Peter Palfrader [Fri, 6 Jul 2018 09:33:19 +0000 (11:33 +0200)]
fix rule
Peter Palfrader [Fri, 6 Jul 2018 09:28:35 +0000 (11:28 +0200)]
disable deflate on security-tracker. we are cpu bound
Peter Palfrader [Fri, 6 Jul 2018 09:21:18 +0000 (11:21 +0200)]
do some basic traffic shaping on soriano
Peter Palfrader [Fri, 6 Jul 2018 08:56:22 +0000 (10:56 +0200)]
enable expires module for security-tracker
Peter Palfrader [Fri, 6 Jul 2018 08:53:32 +0000 (10:53 +0200)]
move apache config for security-tracker.debian.org.conf to puppet
Julien Cristau [Thu, 5 Jul 2018 12:41:38 +0000 (14:41 +0200)]
Kill planet.debian.net (RT#7019)
Julien Cristau [Thu, 5 Jul 2018 12:10:21 +0000 (14:10 +0200)]
The git user's sudo entries should be NOPASSWD (RT#7316)
Peter Palfrader [Thu, 5 Jul 2018 11:22:46 +0000 (13:22 +0200)]
fix rule name
Peter Palfrader [Thu, 5 Jul 2018 11:09:42 +0000 (13:09 +0200)]
snapshot - drop traffic from 61.69.254.110
Julien Cristau [Thu, 5 Jul 2018 11:11:46 +0000 (13:11 +0200)]
Also give the git user sudo access to salsa-* on godard (RT#7316)
Julien Cristau [Thu, 5 Jul 2018 10:31:21 +0000 (12:31 +0200)]
More users for salsa (RT#7316)
Julien Cristau [Thu, 5 Jul 2018 10:02:37 +0000 (12:02 +0200)]
Add registry.salsa.debian.org vhost config (RT#7316)
Julien Cristau [Fri, 29 Jun 2018 14:43:57 +0000 (16:43 +0200)]
unicamp renumbering
Peter Palfrader [Sun, 24 Jun 2018 21:22:47 +0000 (23:22 +0200)]
remove parth, re: RT#7334
Aurelien Jarno [Sun, 24 Jun 2018 21:15:05 +0000 (23:15 +0200)]
setup-all-dchroots: wheezy is gone, jessie is limited to LTS architectures
Julien Cristau [Thu, 21 Jun 2018 06:44:44 +0000 (08:44 +0200)]
get arm-arm-01 out of broken_rtc set
HW's been replaced
Peter Palfrader [Tue, 19 Jun 2018 15:19:20 +0000 (17:19 +0200)]
Install ganeti-reboot-cluster
Julien Cristau [Mon, 18 Jun 2018 18:45:45 +0000 (20:45 +0200)]
Update my home ip ranges yet again
Peter Palfrader [Thu, 7 Jun 2018 19:43:34 +0000 (21:43 +0200)]
set Expires to 1 week also for .gz files
Julien Cristau [Fri, 1 Jun 2018 19:13:26 +0000 (21:13 +0200)]
Enable HTTP/2 on sources.d.o
Peter Palfrader [Fri, 1 Jun 2018 18:24:15 +0000 (20:24 +0200)]
http rate limiting for dynamic hosts also on v6
Peter Palfrader [Fri, 1 Jun 2018 18:12:06 +0000 (20:12 +0200)]
snapshot: allow 6 requests per minute even to clients that we think are excessive
Peter Palfrader [Fri, 1 Jun 2018 16:38:35 +0000 (18:38 +0200)]
snapshot_web dynamic rules
Peter Palfrader [Fri, 1 Jun 2018 16:02:36 +0000 (18:02 +0200)]
snapshot_web dynamic rules
Julien Cristau [Fri, 1 Jun 2018 15:50:02 +0000 (17:50 +0200)]
Drop apache2deb9 variable
All our apaches are stretch at this point.
Julien Cristau [Fri, 1 Jun 2018 15:49:35 +0000 (17:49 +0200)]
Add data-protection@d.o to various exim config bits
Peter Palfrader [Fri, 1 Jun 2018 15:46:34 +0000 (17:46 +0200)]
port 6081 should be allowed via snapshot
Peter Palfrader [Fri, 1 Jun 2018 15:05:55 +0000 (17:05 +0200)]
try apache rate limiting on snapshot hosts, 2
Peter Palfrader [Fri, 1 Jun 2018 15:02:38 +0000 (17:02 +0200)]
try apache rate limiting on snapshot hosts
Peter Palfrader [Fri, 1 Jun 2018 09:11:27 +0000 (11:11 +0200)]
add template
Peter Palfrader [Fri, 1 Jun 2018 09:10:45 +0000 (11:10 +0200)]
parts of the nagios setup
Peter Palfrader [Fri, 1 Jun 2018 09:03:41 +0000 (11:03 +0200)]
nagios: install some packages and define service
Peter Palfrader [Fri, 1 Jun 2018 09:02:33 +0000 (11:02 +0200)]
debian nagios service does not use digest auth
Peter Palfrader [Fri, 1 Jun 2018 09:00:50 +0000 (11:00 +0200)]
nagios: we do not need proxy_http
Peter Palfrader [Fri, 1 Jun 2018 09:00:10 +0000 (11:00 +0200)]
add apache::authn_anon and apache::auth_digest
Peter Palfrader [Fri, 1 Jun 2018 08:58:43 +0000 (10:58 +0200)]
nagios master: apache vhost
Peter Palfrader [Fri, 1 Jun 2018 08:56:10 +0000 (10:56 +0200)]
start using nagios::server again, move cert setup there
Peter Palfrader [Fri, 1 Jun 2018 08:55:41 +0000 (10:55 +0200)]
remove obsolete stuff from nagios::server
Peter Palfrader [Fri, 1 Jun 2018 08:51:02 +0000 (10:51 +0200)]
restart stale icinga automatically
Peter Palfrader [Fri, 1 Jun 2018 07:46:12 +0000 (09:46 +0200)]
wider regex for clearing failed rsyncd service to catch rsyncd-snapshot-farm@
Peter Palfrader [Fri, 1 Jun 2018 07:06:03 +0000 (09:06 +0200)]
ignore ruby-dbi ruby-deprecated ruby-dbd-pg on snapshot hosts
Peter Palfrader [Fri, 1 Jun 2018 07:05:14 +0000 (09:05 +0200)]
ignore ruby-dbi ruby-deprecated ruby-dbd-pg on snapshot hosts
Peter Palfrader [Thu, 31 May 2018 19:20:44 +0000 (21:20 +0200)]
set expires: headers on alioth-archive
Julien Cristau [Thu, 31 May 2018 15:56:31 +0000 (17:56 +0200)]
Add a few pointers on the anonscm index page
Peter Palfrader [Thu, 31 May 2018 15:46:27 +0000 (17:46 +0200)]
index page for anonscm, 2
Peter Palfrader [Thu, 31 May 2018 15:45:20 +0000 (17:45 +0200)]
index page for anonscm
Peter Palfrader [Thu, 31 May 2018 15:44:08 +0000 (17:44 +0200)]
put an /srv/anonscm.debian.org/htdocs in place
Peter Palfrader [Thu, 31 May 2018 15:38:22 +0000 (17:38 +0200)]
vhost cleanup
Peter Palfrader [Thu, 31 May 2018 15:33:19 +0000 (17:33 +0200)]
vhost update
Peter Palfrader [Thu, 31 May 2018 15:28:50 +0000 (17:28 +0200)]
non-SSL is on 80
Peter Palfrader [Thu, 31 May 2018 15:25:05 +0000 (17:25 +0200)]
Use anonscm.map
Peter Palfrader [Thu, 31 May 2018 15:24:19 +0000 (17:24 +0200)]
try to put anonscm.map onto host, 3
Peter Palfrader [Thu, 31 May 2018 15:23:32 +0000 (17:23 +0200)]
try to put anonscm.map onto host, 2
Peter Palfrader [Thu, 31 May 2018 15:22:07 +0000 (17:22 +0200)]
try to put anonscm.map onto host
Peter Palfrader [Thu, 31 May 2018 15:15:38 +0000 (17:15 +0200)]
prepare anonscm vhost
Peter Palfrader [Wed, 30 May 2018 12:16:25 +0000 (14:16 +0200)]
set hsts on snapshot
Peter Palfrader [Wed, 30 May 2018 08:24:46 +0000 (10:24 +0200)]
Try to put haproxy on snapshot hosts
Peter Palfrader [Wed, 30 May 2018 08:18:57 +0000 (10:18 +0200)]
Add a logging device for haproxy
Peter Palfrader [Wed, 30 May 2018 08:17:08 +0000 (10:17 +0200)]
Add haproxy module from tor
Peter Palfrader [Wed, 30 May 2018 08:16:25 +0000 (10:16 +0200)]
a haproxy facter
Peter Palfrader [Wed, 30 May 2018 08:00:54 +0000 (10:00 +0200)]
More verbose setup-all-dchroots when run in a terminal
Peter Palfrader [Tue, 29 May 2018 14:24:02 +0000 (16:24 +0200)]
install snapshot cert
Peter Palfrader [Tue, 29 May 2018 12:37:24 +0000 (14:37 +0200)]
sallinen: retire 443->5473 dnat
Peter Palfrader [Tue, 29 May 2018 09:37:43 +0000 (11:37 +0200)]
Fetch sallinen.debian.org snapshot backups from port 5473
Peter Palfrader [Mon, 28 May 2018 21:59:50 +0000 (23:59 +0200)]
pg ssh auth: danzi: remove read for sibelius; lw07: switch read sibelius to read sallinen; sallinen: remove read sibelius
Peter Palfrader [Mon, 28 May 2018 21:57:06 +0000 (23:57 +0200)]
backup sallinen pg
Peter Palfrader [Mon, 28 May 2018 21:54:27 +0000 (23:54 +0200)]
sallinen has a pg server
Peter Palfrader [Mon, 28 May 2018 21:25:30 +0000 (23:25 +0200)]
pg firewalling
Peter Palfrader [Mon, 28 May 2018 21:12:24 +0000 (23:12 +0200)]
add lw07 to snapshot_web group
Peter Palfrader [Mon, 28 May 2018 18:13:08 +0000 (20:13 +0200)]
start varnish only after network is online
Peter Palfrader [Mon, 28 May 2018 18:09:54 +0000 (20:09 +0200)]
Try an network_online target for stretch hosts
Peter Palfrader [Mon, 28 May 2018 09:20:57 +0000 (11:20 +0200)]
And setup ferm, 2
Peter Palfrader [Mon, 28 May 2018 09:19:34 +0000 (11:19 +0200)]
And setup ferm
Peter Palfrader [Mon, 28 May 2018 09:15:22 +0000 (11:15 +0200)]
add -j unix,user=vcache -F to varnishd call
Peter Palfrader [Mon, 28 May 2018 08:54:40 +0000 (10:54 +0200)]
and use array for listening ports
Peter Palfrader [Mon, 28 May 2018 08:53:11 +0000 (10:53 +0200)]
varnish on stretch now takes several -a arguments instead of one with multiple addresses
Peter Palfrader [Mon, 28 May 2018 08:40:16 +0000 (10:40 +0200)]
sallinen varnish, 2
Peter Palfrader [Mon, 28 May 2018 08:37:24 +0000 (10:37 +0200)]
sallinen varnish
Peter Palfrader [Mon, 28 May 2018 08:19:18 +0000 (10:19 +0200)]
a very basic generic varnish module
Peter Palfrader [Mon, 28 May 2018 08:10:15 +0000 (10:10 +0200)]
rename varnish to varnish_pkgmirror module
Peter Palfrader [Mon, 28 May 2018 08:09:17 +0000 (10:09 +0200)]
rename varnish to varnish_pkgmirror module
Peter Palfrader [Sun, 20 May 2018 08:41:31 +0000 (10:41 +0200)]
allow archvsync to trigger snapshot imports
Martin Zobel-Helas [Wed, 9 May 2018 23:06:09 +0000 (01:06 +0200)]
block mails from @qq.com
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Julien Cristau [Tue, 8 May 2018 10:39:38 +0000 (12:39 +0200)]
fix kanboard role (php wants mpm_prefork)
Julien Cristau [Tue, 8 May 2018 10:36:13 +0000 (12:36 +0200)]
add a kanboard role
Julien Cristau [Tue, 8 May 2018 10:32:27 +0000 (12:32 +0200)]
kanboard group members can run stuff as kanboard on kantuser
Aurelien Jarno [Sun, 6 May 2018 20:46:10 +0000 (22:46 +0200)]
Fixup previous commit, log directory permissions were already defined
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>